Impact
The Product Shortlist WordPress plugin up to version 1.0.4 fails to properly sanitize a request parameter before using it in a SQL query. This flaw allows unauthenticated attackers to inject arbitrary SQL code via the get_shortlisted_products endpoint. The injection can lead to unauthorized disclosure of database contents or modification of data, compromising the confidentiality and integrity of the site.
Affected Systems
WordPress sites that have the Product Shortlist plugin installed with a version equal to or earlier than 1.0.4 are affected. No vendor’s official name is provided; the plugin is known simply as 'Product Shortlist' and can be verified by checking the plugin directory or the readme file.
Risk and Exploitability
The CVSS score of 8.6 classifies this as high severity, but the EPSS score is below 1 %, indicating that active exploitation is currently considered unlikely. The vulnerability is not listed in the CISA KEV catalog. An attacker can craft requests without authentication, so the web-based attack vector increases the potential for exploitation. High impact potential warrants prompt action despite low current exploitation probability.
OpenCVE Enrichment